Trusted Execution Environment Key Migration via Certificate Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional key migration techniques in symmetric and asymmetric cryptography are overly reliant on complex hardware systems, lack specificity in controlling key migration, and are not suitable for non-local deployment environments, posing security risks and practical challenges in provisioning and trusting migration authorities.

Innovation Solution

A secure key management system using a Trusted Execution Environment (TEE) with a client and a Certificate Authority (CA) for secure key enrollment, export, and import, employing flags for migration authorization and Sigma protocol for secure channel establishment, allowing secure and targeted key migration without relying on physically moving hardware or manual PIN-based methods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional key migration techniques are used, then key migration can be performed, but the system becomes overly reliant on complex hardware systems and lacks specificity in controlling key migration

Engineering Contradiction:
Improvekey migration control specificityVSAvoidhardware system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent replaces complex hardware-based key migration systems with a software-based solution using Trusted Execution Environments (TEE). The TEE provides a secure virtual boundary that enables key migration through cryptographic operations rather than physical hardware manipulation, thereby reducing hardware complexity while maintaining security and increasing control specificity through software-defined policies.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a Migration Authority (MA) as an intermediary entity that mediates key migration between different TEEs. The MA uses cryptographic tokens and certificates to enable controlled key transfer without requiring direct hardware connections or manual intervention, thus simplifying the system architecture while providing fine-grained control over migration operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual PIN-based key migration methods are used, then key migration can be performed, but security risks increase and the method is not suitable for non-local deployment environments

Engineering Contradiction:
Improvekey migration securityVSAvoiddeployment flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces manual PIN-based key migration with automated cryptographic operations within TEEs. The system uses machine-to-machine authentication through certificates and tokens, eliminating the need for human intervention and manual PIN entry. This substitution enhances security by removing human error vulnerabilities while improving deployment flexibility for non-local environments through automated remote key migration.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The TEE system performs self-service key migration operations by automatically generating cryptographic tokens, validating certificates, and executing key transfer protocols without requiring manual user input. The system autonomously manages the key migration process, including secure storage, encryption, and transmission, thereby improving both security and ease of operation in distributed environments.

Inventive Principle:
Principle #25Self-service

3Reliability

If complex hardware systems are used for key migration, then key security can be maintained, but the infrastructure becomes overly complex and difficult to provision

Engineering Contradiction:
Improvekey securityVSAvoidinfrastructure provisioning
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent creates a universal key migration framework based on TEEs that can operate across diverse hardware platforms and deployment scenarios. The TEE provides a standardized secure boundary that works whether keys are stored locally or remotely, eliminating the need for different hardware systems for different deployment types. This universality simplifies infrastructure provisioning while maintaining security through a consistent cryptographic approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The Migration Authority serves as a universal intermediary that handles key migration for all TEEs regardless of their specific hardware implementation or deployment location. The MA uses standardized cryptographic protocols to mediate key transfer, eliminating the need for complex custom hardware provisioning for each scenario and simplifying infrastructure setup while maintaining security through centralized cryptographic control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9602500B2Secure import and export of keying material
Publication Date: 2017.03.21 INTEL CORP
  • US9602500B2 patent drawing
  • US9602500B2 patent drawing
  • US9602500B2 patent drawing

AI summary

An embodiment includes a method executed by at least one processor of a first computing node comprising: generating a key pair including a first public key and a corresponding first private key; receiving an instance of a certificate, including a second public key, from a second computing node located remotely from the first computing node; associating the instance of the certificate with the key pair; receiving an additional instance of the certificate; verifying the additional instance of the certificate is associated with the key pair; and encrypting and exporting the first private key in response to verifying the additional instance of the certificate is associated with the key pair. Other embodiments are described herein.